Recently Updated Pages
Break Glass
Default deny is a wonderful thing, the best place to be - except when you lock yourself out. Than...
Manual Access
Default deny is the best way to live. However sometimes you need to manually grant access for a n...
Windows Firewall
Microsoft Windows comes equipped with a built-in native firewall which Knocknoc orchestrates to p...
Updates and upgrades
The Knocknoc software is managed by your operating system, as such updates can be managed within ...
SAML with EntraID (Azure AD)
The following example assumes your Knocknoc instance is located at https://<hosting instance>.kno...
Fortigate Address Groups (Fortinet)
The FortiOS integration allows Knocknoc to dynamically add and remove user's source IP from a na...
AWS (EC2) Security Groups
Knocknoc can orchestrate Amazon AWS Security Groups, which essentially provide network level fire...
Custom Script
The "Custom Script" Knoc type is simply a script the agent can execute directly on the Agent mach...
Moving from SQLite to PostgreSQL
If you installed Knocknoc Server before version 8.5 (September 2025), your instance is likely usi...
Server installation (on premise)
On a Linux host as Root, execute the below command to setup and install your Knocknoc server. You...
Create users
User creation varies depending on the authentication source in use. "SAML users" are created on-t...
Windows Servers
Windows Servers and RDP/WinRM - removing pre-auth attack surface A mid-sized business utilizes R...
Use cases (overview)
Knocknoc use cases Knocknoc is extremely versatile and can enable just in time network access co...
Logging
Logging is important - we love logging. Because of this, we have included an easy to find, follo...
SaaS deployment
To create a SaaS Server instance (we host it) log in to the licensing portal and follow the promp...
Local Authentication (MFA included)
Knocknoc supports local users in addition to SAML/LDAP. Simply add a user, with a username and p...
v8.5
Knocknoc 8.5 Knocknoc 8.5 delivers key improvements in usability, integrations, and security, ...
High availability
The Knocknoc Server can be deployed in various ways to match your high-availability needs and dep...
Knocknoc Reverse Proxy
The Knocknoc orchestration Agent - which is deployed alongside managed infrastructure (not on des...
HAProxy + KAT
Sometimes IP address restrictions or IP-based allowlisting is not enough, think: airport lounge, ...